CVE-2022-3830: WP Page Builder <= 1.2.8 - Admin+ Stored Cross-Site
The WP Page Builder WordPress plugin through 1.2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-3830?
The severity of CVE-2022-3830 is medium with a CVSS score of 4.8.
What is the affected software of CVE-2022-3830?
The affected software of CVE-2022-3830 is the WP Page Builder WordPress plugin through version 1.2.8.
What is the vulnerability type of CVE-2022-3830?
The vulnerability type of CVE-2022-3830 is Stored Cross-Site Scripting (Stored XSS).
How can a high privilege user exploit CVE-2022-3830?
A high privilege user, such as an admin, can exploit CVE-2022-3830 through Stored Cross-Site Scripting (Stored XSS) attacks.
Is the WP Page Builder plugin patched for CVE-2022-3830?
There is no information available about a patch for CVE-2022-3830 at the moment. It is recommended to update to the latest version of the WP Page Builder plugin if available.